SD-WAN Overlay-as-a-Service
SD-WAN Overlay-as-a-Service (OaaS) is supported through a license displayed as SD-WAN Overlay as a Service on the System > FortiGuard page. Each FortiGate used by the FortiCloud Overlay-as-a-Service portal must have this license applied to it.
To view the status of the OaaS license in the GUI:
-
Go to System > FortiGuard.
-
Expand License Information. The SD-WAN Overlay as a Service license status is listed as:
-
Licensed: OaaS is currently licensed and will expire on the provided date.
-
Expires Soon: OaaS is currently licensed but will expire soon on the provided date.
-
Expired: The OaaS license has already expired on the provided date.
-
Not Licensed: OaaS has not been licensed.
-
To view the status of the OaaS license in the CLI:
-
Verify that the entitlement can be updated:
The SD-WAN Overlay-as-a-Service license is listed as
SWOS
in the CLI.# diagnose test update info System contracts: FMWR,Wed Dec 20 16:00:00 2023 SPAM,Wed Dec 20 16:00:00 2023 SBCL,Wed Dec 20 16:00:00 2023 SWNO,Wed Dec 20 16:00:00 2023 SWNM,Wed Sep 27 17:00:00 2023 SWOS,Mon Aug 14 17:00:00 2023 SPRT,Wed Dec 20 16:00:00 2023 SDWN,Sun Dec 10 16:00:00 2023 SBCL,Wed Dec 20 16:00:00 2023 SBEN,Wed Dec 20 16:00:00 2023
-
Verify that the expiration date log can be generated:
# execute log display 1: date=2023-08-10 time=00:00:01 eventtime=1691650800645347120 tz="-0700" logid="0100020138" type="event" subtype="system" level="warning" vd="root" logdesc="FortiGuard SD-WAN Overlay as a Service license expiring" msg="FortiGuard SD-WAN Overlay Service license will expire in 4 day(s)"
To ensure FortiGate spoke traffic remains uninterrupted when configuration is orchestrated from the SD-WAN Overlay-as-a-Service (OaaS), support for an OaaS agent on the FortiGate is available. The OaaS agent communicates with the OaaS controller in FortiCloud, validates and compares the FortiOS configuration, and applies the FortiOS configuration to the FortiGate as a transaction when it has been orchestrated from the OaaS portal. Secure communication between the OaaS agent and the OaaS controller is achieved using the FGFM management tunnel.
If any configuration change fails to be applied, then the OaaS agent rolls back all configuration changes that were orchestrated. The OaaS status can be acquired using get oaas status
.
To determine the status of OaaS:
# get oaas status Account ID: 78992 Account: admin@domain.com Site: site1 Configuration version: 4 Configuration sync status: SUCCESS Target version: 4 Task ID: xxxxxxxxx Error: